Fallos del tipo CWE-918

3086 resultados

Server-Side Request Forgery (SSRF)

Ocorre quando a aplicação web busca conteúdo de uma URL fornecida pelo usuário sem validar adequadamente o destino. Um atacante consegue fazer o servidor requisitar URLs não autorizadas — internas, administrativas ou de terceiros — aproveitando a confiança e as permissões que o servidor possui na rede.

Ejemplo

Um sistema permite gerar thumbnails de imagens externas: o usuário passa uma URL e o servidor faz o download. Um atacante envia 'http://localhost:8080/admin' e consegue acessar painéis administrativos internos que não deveria. Ou envia 'http://169.254.169.254/latest/meta-data' em ambientes AWS e rouba credenciais.

Cómo mitigar

Mantenha uma whitelist rigorosa de domínios e IPs permitidos; bloqueie ranges privados (10.0.0.0/8, 127.0.0.0/8, 169.254.0.0/16) e metadados-servers por padrão; valide URLs antes de fazer requisições; use bibliotecas de parsing robustas; considere isolamento de rede para requisições externas.

CVE-2026-44502MEDIUMBugsink: SSRF bypass in `validate_webhook_url`EPSS 0.4%CVE-2026-4366MEDIUMKeycloak-services: blind server-side request forgery (ssrf) via http redirect handling in keycloakEPSS 0.4%CVE-2026-13739HIGHServer-Side Request Forgery (SSRF)EPSS 0.4%CVE-2026-15643CRITICALAWS HealthLake MCP Server SSRF via Pagination URLEPSS 0.4%CVE-2026-4964MEDIUMletta-ai letta File URL message_helper.py _convert_message_create_to_message server-side request forgeryEPSS 0.4%CVE-2026-33540HIGHDistribution affected by pull-through cache credential exfiltration via www-authenticate bearer realmEPSS 0.4%CVE-2025-2691HIGHVersions of the package nossrf before 1.0.4 are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provide a hostname thEPSS 0.4%CVE-2026-34504MEDIUMOpenClaw < 2026.3.28 - Server-Side Request Forgery via Unguarded Image Download in fal ProviderEPSS 0.4%CVE-2026-5052MEDIUMVault Vulnerable to Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNSEPSS 0.4%CVE-2026-48858MEDIUMftp client PASV response IP not validated against control peer, enabling SSRF and FTP bounce attacksEPSS 0.4%CVE-2026-92932MEDIUMMISP sachertortephp Xml::build() Operator Precedence Bypass Allows Unintended HTTPS SSRF When readFile Is DisabledEPSS 0.4%CVE-2026-34966HIGHGitea prior to 1.27.0 SSRF via Migration URI Fetch BypassEPSS 0.4%CVE-2025-13281MEDIUMPortworx Half-Blind SSRF in kube-controller-managerEPSS 0.4%CVE-2026-42184MEDIUMTauri: Origin Confusion Allows Remote Pages to Invoke Local-Only IPC CommandsEPSS 0.4%CVE-2026-55455MEDIUMAppsmith: SSRF in REST API / GraphQL datasource plugins via insufficient host denylistEPSS 0.4%CVE-2026-73432MEDIUMStored Server-Side Request Forgery in Remote-Instance Synchronization Allows Access to Internal Services in vulnerability-lookupEPSS 0.4%CVE-2026-53927MEDIUMNocoDB: Server-Side Request Forgery via Spreadsheet Fetch URLEPSS 0.4%CVE-2026-57940LOWHTMLy 3.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the RSS feed import functionality. The function get_feed() in sysEPSS 0.4%CVE-2026-12473HIGHOHIF Viewers DICOM Server-Side request forgeryEPSS 0.4%CVE-2026-68558HIGHWekan: SSRF filter bypass via DNS-resolving hostname in outgoing webhooks (incomplete fix of CVE-2026-53446)EPSS 0.4%